New issue
Advanced search Search tips
Note: Color blocks (like or ) mean that a user may not be available. Tooltip shows the reason.

Issue 619381 link

Starred by 1 user

Issue metadata

Status: Verified
Owner:
Last visit > 30 days ago
Closed: Aug 2016
Cc:
Components:
EstimatedDays: ----
NextAction: ----
OS: Mac
Pri: 1
Type: Bug-Security



Sign in to add a comment

Crash in GrCircleBlurFragmentProcessor::CreateCircleBlurProfileTexture

Project Member Reported by ClusterFuzz, Jun 12 2016

Issue description

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5032270918582272

Fuzzer: bj_broddelwerk
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: UNKNOWN
Crash Address: 0x624e000cff00
Crash State:
  GrCircleBlurFragmentProcessor::CreateCircleBlurProfileTexture
  GrCircleBlurFragmentProcessor::Create
  GrRRectBlurEffect::Create
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_chrome&range=395419:395560

Minimized Testcase (1.07 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97rlWFPCOwOm-3Q9gjkuOgkqY_ubrNSgxlwwlMABVJoJeL5DtRHJu-9razPJspi_Vomx7524zSZT5nPTR-KLrdUi4O9ICRuL1zeuiT_w0ziFF_hQM6PCVZr_3aRSJEfyfSAT4KzjyTR8uDVpq-AYDPkrIQsKg

Filer: inferno

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
 
Owner: bsalomon@chromium.org
Status: Assigned (was: Available)

Author: bsalomon
Project: chromium-skia
Changelist: https://chromium.googlesource.com/skia.git/+/82ad93c356d8c010e1260224c86ce6f74359a2da
Time: Fri May 20 16:11:17 2016
The CL last changed line 162 of file GrCircleBlurFragmentProcessor.cpp, which is stack frame 0.
Project Member

Comment 2 by sheriffbot@chromium.org, Jun 12 2016

Labels: Pri-1
Components: Internals>Skia
Labels: M-51
Project Member

Comment 4 by sheriffbot@chromium.org, Jun 14 2016

Labels: -Security_Impact-Head Security_Impact-Stable
Project Member

Comment 5 by ClusterFuzz, Jun 17 2016

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6173107731824640

Fuzzer: bj_broddelwerk
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: UNKNOWN
Crash Address: 0x604e00045998
Crash State:
  GrCircleBlurFragmentProcessor::CreateCircleBlurProfileTexture
  GrCircleBlurFragmentProcessor::Make
  GrRRectBlurEffect::Make
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_chrome&range=395419:395560

Minimized Testcase (0.60 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96in2NUt6wGcX-y4XqV3GYbdfaDYfT7_q2TiDANAQFA12iUQSjoNmk2Q12h0oUrbhjw0LUpVzsnewWzrPrs0_tyJmlg10NZZcG0i_9g855hcATPOIoYxd-BrHcMx1GkqgerAJLvfadLdg9UyBUqSwKUCvIGnQ

Filer: inferno

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.
Project Member

Comment 6 by sheriffbot@chromium.org, Jun 26 2016

bsalomon: Uh oh! This issue still open and hasn't been updated in the last 14 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one?

If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 7 by sheriffbot@chromium.org, Jul 10 2016

bsalomon: Uh oh! This issue still open and hasn't been updated in the last 28 days. This is a serious vulnerability, and we want to ensure that there's progress. Could you please leave an update with the current status and any potential blockers?

If you're not the right owner for this issue, could you please remove yourself as soon as possible or help us find the right one?

If the issue is fixed or you can't reproduce it, please close the bug. If you've started working on a fix, please set the status to Started.

Thanks for your time! To disable nags, add the Disable-Nags label.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot
Project Member

Comment 8 by sheriffbot@chromium.org, Jul 21 2016

Labels: -M-51 M-52
Cc: reed@chromium.org rmis...@chromium.org
This hasn't had any updates for a couple of months. 

reed/rmistry/bsalomon: could you please help triage? Thanks!
I have a repro of this.
Project Member

Comment 11 by ClusterFuzz, Aug 17 2016

ClusterFuzz has detected this issue as fixed in range 412227:412240.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=6173107731824640

Fuzzer: bj_broddelwerk
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: UNKNOWN
Crash Address: 0x604e00045998
Crash State:
  GrCircleBlurFragmentProcessor::CreateCircleBlurProfileTexture
  GrCircleBlurFragmentProcessor::Make
  GrRRectBlurEffect::Make
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_chrome&range=395419:395560
Fixed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_chrome&range=412227:412240

Minimized Testcase (0.60 Kb): https://cluster-fuzz.appspot.com/download/AMIfv96in2NUt6wGcX-y4XqV3GYbdfaDYfT7_q2TiDANAQFA12iUQSjoNmk2Q12h0oUrbhjw0LUpVzsnewWzrPrs0_tyJmlg10NZZcG0i_9g855hcATPOIoYxd-BrHcMx1GkqgerAJLvfadLdg9UyBUqSwKUCvIGnQ?testcase_id=6173107731824640

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 12 by ClusterFuzz, Aug 17 2016

ClusterFuzz has detected this issue as fixed in range 412269:412297.

Detailed report: https://cluster-fuzz.appspot.com/testcase?key=5032270918582272

Fuzzer: bj_broddelwerk
Job Type: mac_asan_chrome
Platform Id: mac

Crash Type: UNKNOWN
Crash Address: 0x624e000cff00
Crash State:
  GrCircleBlurFragmentProcessor::CreateCircleBlurProfileTexture
  GrCircleBlurFragmentProcessor::Create
  GrRRectBlurEffect::Create
  
Recommended Security Severity: Medium

Regressed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_chrome&range=395419:395560
Fixed: https://cluster-fuzz.appspot.com/revisions?job=mac_asan_chrome&range=412269:412297

Minimized Testcase (1.07 Kb): https://cluster-fuzz.appspot.com/download/AMIfv97rlWFPCOwOm-3Q9gjkuOgkqY_ubrNSgxlwwlMABVJoJeL5DtRHJu-9razPJspi_Vomx7524zSZT5nPTR-KLrdUi4O9ICRuL1zeuiT_w0ziFF_hQM6PCVZr_3aRSJEfyfSAT4KzjyTR8uDVpq-AYDPkrIQsKg?testcase_id=5032270918582272

See https://dev.chromium.org/Home/chromium-security/bugs/reproducing-clusterfuzz-bugs for more information.

If you suspect that the result above is incorrect, try re-doing that job on the test case report page.
Project Member

Comment 13 by ClusterFuzz, Aug 17 2016

Labels: ClusterFuzz-Verified
Status: Verified (was: Assigned)
ClusterFuzz testcase is verified as fixed, closing issue.

If this is incorrect, please add ClusterFuzz-Wrong label and re-open the issue.
Project Member

Comment 14 by sheriffbot@chromium.org, Aug 17 2016

Labels: -Restrict-View-SecurityTeam Restrict-View-SecurityNotify
Project Member

Comment 15 by sheriffbot@chromium.org, Nov 23 2016

Labels: -Restrict-View-SecurityNotify allpublic
This bug has been closed for more than 14 weeks. Removing security view restrictions.

For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot

Sign in to add a comment